Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total153
Critical10
High27
Medium112
Reset
Showing 41-60 of 153 records
Threat Entry Updated 2025-05-15

CVE-2024-10493 - Before 5 Plugin

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2024-10493

MEDIUM CVSS 5.4 2024-11-28
Threat Entry Updated 2025-06-12

CVE-2024-10103 - Before 5 Plugin

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

PLUGIN Before 5

CVE-2024-10103

MEDIUM CVSS 6.1 2024-11-19
Threat Entry Updated 2025-05-27

CVE-2024-6724 - Before 5 Plugin

The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2024-6724

MEDIUM CVSS 4.8 2024-08-13
Threat Entry Updated 2025-08-25

CVE-2024-6420 - Before 5 Plugin

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

PLUGIN Before 5

CVE-2024-6420

HIGH CVSS 8.6 2024-07-23
Threat Entry Updated 2024-11-21

CVE-2024-4704 - Before 5 Plugin

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

PLUGIN Before 5

CVE-2024-4704

MEDIUM CVSS 6.1 2024-06-27
Threat Entry Updated 2025-05-08

CVE-2024-3478 - Before 5 Plugin

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

PLUGIN Before 5

CVE-2024-3478

MEDIUM CVSS 6.1 2024-05-02
Threat Entry Updated 2025-05-08

CVE-2024-3472 - Before 5 Plugin

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

PLUGIN Before 5

CVE-2024-3472

MEDIUM CVSS 5.9 2024-05-02
Threat Entry Updated 2025-05-30

CVE-2024-2309 - Before 5 Plugin

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2024-2309

MEDIUM CVSS 4.8 2024-04-17
Threat Entry Updated 2025-05-15

CVE-2024-1204 - Before 5 Plugin

The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitrary custom fields assigned to other user's posts.

PLUGIN Before 5

CVE-2024-1204

MEDIUM CVSS 4.3 2024-04-15
Threat Entry Updated 2025-05-05

CVE-2024-1331 - Before 5 Plugin

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2024-1331

MEDIUM CVSS 6.1 2024-03-18
Threat Entry Updated 2025-05-05

CVE-2024-1333 - Before 5 Plugin

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

PLUGIN Before 5

CVE-2024-1333

MEDIUM CVSS 5.4 2024-03-18
Threat Entry Updated 2025-06-27

CVE-2024-1316 - Before 5 Plugin

The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).

PLUGIN Before 5

CVE-2024-1316

MEDIUM CVSS 6.5 2024-03-04
Threat Entry Updated 2025-04-24

CVE-2024-1319 - Before 5 Plugin

The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

PLUGIN Before 5

CVE-2024-1319

MEDIUM CVSS 4.3 2024-03-04
Threat Entry Updated 2025-06-02

CVE-2023-0079 - Before 5 Plugin

The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PLUGIN Before 5

CVE-2023-0079

MEDIUM CVSS 5.4 2024-01-16
Threat Entry Updated 2024-11-21

CVE-2023-5348 - Before 5 Plugin

The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.

PLUGIN Before 5

CVE-2023-5348

MEDIUM CVSS 6.1 2023-12-18
Threat Entry Updated 2024-11-21

CVE-2023-5845 - Before 5 Plugin

The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags

PLUGIN Before 5

CVE-2023-5845

MEDIUM CVSS 5.3 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-4642 - Before 5 Plugin

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

PLUGIN Before 5

CVE-2023-4642

MEDIUM CVSS 5.9 2023-11-27
Threat Entry Updated 2024-11-21

CVE-2023-5140 - Before 5 Plugin

The Bonus for Woo WordPress plugin before 5.8.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Before 5

CVE-2023-5140

MEDIUM CVSS 6.1 2023-11-20
Threat Entry Updated 2025-02-26

CVE-2023-4810 - Before 5 Plugin

The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Before 5

CVE-2023-4810

MEDIUM CVSS 4.8 2023-11-06
Threat Entry Updated 2025-04-23

CVE-2023-4318 - Before 5 Plugin

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

PLUGIN Before 5

CVE-2023-4318

MEDIUM CVSS 4.3 2023-09-11
Scroll to top